Ubuntu Security Update USN-7664-1: Sinatra vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,806
Reaction score
74
Credits
-1,257
It was discovered that Sinatra incorrectly handled serving static files. An attacker could possibly use this issue to perform local file inclusion, obtaining sensitive information. (CVE-2022-29970) It was discovered that Sinatra incorrectly handled special characters in the Content-Disposition HTTP header. An attacker could possibly use this issue to perform a reflected file download attack, achieving remote code execution. (CVE-2022-45442)

Continue reading...
 


Follow Linux.org

Members online


Latest posts

Top